Disable Admin Notices – Hide Dashboard Notifications Security & Risk Analysis

wordpress.org/plugins/disable-admin-notices

Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.

100K active installs v1.4.3 PHP 7.4+ WP 5.6+ Updated Feb 17, 2026
admin-noticeshide-admin-noticeshide-admin-notificationsnnotificationsupdate-notifications
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 24, 2026
Safety Verdict

Is Disable Admin Notices – Hide Dashboard Notifications Safe to Use in 2026?

Generally Safe

Score 98/100

Disable Admin Notices – Hide Dashboard Notifications has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 24, 2026Updated 1mo ago
Risk Assessment

The 'disable-admin-notices' plugin v1.4.3 exhibits a mixed security posture. While the static analysis reveals a relatively small attack surface with all identified entry points (AJAX handlers) protected by authentication checks, and no dangerous functions or file operations, there are significant concerns regarding data handling. The complete lack of prepared statements for SQL queries is a major red flag, potentially exposing the site to SQL injection vulnerabilities. Furthermore, the relatively low percentage of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities.

The vulnerability history indicates a past pattern of medium severity vulnerabilities, primarily Cross-Site Request Forgery (CSRF). Although there are currently no unpatched CVEs, the historical trend of medium severity issues, coupled with the code analysis findings of raw SQL and insufficient output escaping, suggests a potential for future vulnerabilities if these issues are not addressed. The plugin does demonstrate good practices in its use of nonces and capability checks, and the absence of external HTTP requests and bundled libraries is a positive. However, the data handling deficiencies in the code and the historical vulnerability pattern warrant careful consideration.

Key Concerns

  • SQL queries do not use prepared statements
  • Only 59% of output is properly escaped
  • 2 medium severity CVEs in history
Vulnerabilities
2

Disable Admin Notices – Hide Dashboard Notifications Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-2410medium · 4.3Cross-Site Request Forgery (CSRF)

Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update

Feb 24, 2026 Patched in 1.4.3 (1d)
CVE-2024-52420medium · 4.3Cross-Site Request Forgery (CSRF)

Disable Admin Notices individually <= 1.4.0 - Cross-Site Request Forgery

Nov 13, 2024 Patched in 1.4.1 (402d)
Code Analysis
Analyzed Mar 16, 2026

Disable Admin Notices – Hide Dashboard Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
17
24 escaped
Nonce Checks
8
Capability Checks
11
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

59% escaped41 total outputs
Attack Surface

Disable Admin Notices – Hide Dashboard Notifications Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_wdan-disable-adminbar-menusadmin\ajax\disable-adminbar-menus.php:40
authwp_ajax_wbcr-dan-hide-noticesadmin\ajax\hide-notice.php:63
authwp_ajax_wbcr-dan-restore-noticeadmin\ajax\restore-notice.php:49
WordPress Hooks 26
filterwbcr_factory_pages_480_imppage_rating_widget_urladmin\boot.php:33
filterwbcr/factory/pages/impressive/widgetsadmin\boot.php:48
filterwbcr_clearfy_group_optionsadmin\boot.php:65
filterwbcr_clr_additionally_form_optionsadmin\options.php:194
actionwp_before_admin_bar_renderadmin\pages\class-pages-edit-admin-bar.php:60
filterwp_redirectadmin\pages\class-pages-edit-redirects.php:60
actionadmin_noticesclearfy.php:49
actionnetwork_admin_noticesclearfy.php:50
actionadmin_noticesdisable-admin-notices.php:174
actionnetwork_admin_noticesdisable-admin-notices.php:175
actioninitincludes\class-plugin.php:46
filterthemeisle_sdk_productsincludes\class-plugin.php:52
filterthemeisle_sdk_ran_promosincludes\class-plugin.php:54
actionadmin_headincludes\classes\class-configurate-notices.php:25
actionadmin_headincludes\classes\class-configurate-notices.php:30
actionadmin_print_scriptsincludes\classes\class-configurate-notices.php:31
actionadmin_print_footer_scriptsincludes\classes\class-configurate-notices.php:32
filterwdan/notifications/allincludes\classes\class-configurate-notices.php:34
actionwdn/notifications/panel/allincludes\classes\class-configurate-notices.php:35
filterwdn/notifications/catch/allincludes\classes\class-configurate-notices.php:36
actionadmin_print_scriptsincludes\classes\class-configurate-notices.php:41
actionadmin_bar_menuincludes\classes\class-configurate-notices.php:42
actionadmin_enqueue_scriptsincludes\classes\class-configurate-notices.php:43
actionnetwork_admin_noticesincludes\classes\class-configurate-notices.php:51
actionadmin_noticesincludes\classes\class-configurate-notices.php:53
actionadmin_noticesincludes\classes\class-configurate-notices.php:531
Maintenance & Trust

Disable Admin Notices – Hide Dashboard Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads1.4M

Community Trust

Rating94/100
Number of ratings348
Active installs100K
Developer Profile

Disable Admin Notices – Hide Dashboard Notifications Developer Profile

Themeisle

37 plugins · 2.2M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
420 days
View full developer profile
Detection Fingerprints

How We Detect Disable Admin Notices – Hide Dashboard Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disable-admin-notices/admin/assets/css/general.css/wp-content/plugins/disable-admin-notices/admin/assets/js/notice.js
Script Paths
/wp-content/plugins/disable-admin-notices/admin/assets/js/notice.js
Version Parameters
wbcr-notification-hide-style

HTML / DOM Fingerprints

CSS Classes
wbcr-notice-hide-itemwbcr-notice-hide-titlewbcr-notice-hide-description
Data Attributes
data-notice-id
JS Globals
wbcr_admin_noticewbcr_admin_notice_control
FAQ

Frequently Asked Questions about Disable Admin Notices – Hide Dashboard Notifications